updated ESD in light of post-EFAIL security vulnerabilities around spoofing signatures.